US2018018665A1PendingUtilityA1

Method and device for accessing a service

Assignee: GEMALTO SAPriority: Feb 2, 2015Filed: Feb 2, 2016Published: Jan 18, 2018
Est. expiryFeb 2, 2035(~8.5 yrs left)· nominal 20-yr term from priority
H04L 2209/56H04L 9/3247H04L 9/30G06Q 20/401H04L 9/14G06F 21/64G06Q 2220/00G06F 21/35G06F 21/71H04L 63/0492G06F 21/77G06F 2221/2153G06F 2221/2151G06Q 30/0601G06F 2221/2107G06Q 10/02G06F 2221/2101H04L 63/0823G06F 21/72G06F 2221/2115H04L 63/0853H04W 4/12
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In a method for accessing a service, a device receives data. The device gets, based upon the received data, transaction data. The device signs the transaction data by using a private key relating to a transaction processing, a signature operation result being a transaction signature. The device generates a transaction analysis result. The device stores the transaction data and the transaction signature. The device analyses whether the transaction analysis result is or is not a transaction authorization. Only if the transaction analysis result is a transaction authorization, the device gets, based upon the received data, service data. The device sends to a first external entity the service data. The device sends the transaction data and the transaction signature to either the first external entity or a second external entity.

Claims

exact text as granted — not AI-modified
1 . A method for accessing a service, with a device comprising data storing means, wherein the method comprises the following steps:
 receiving, by the device, data;   getting, by the device, based upon the received data, transaction data;   signing, by the device, the transaction data by using a private key relating to a transaction processing, a signature operation result being a transaction signature;   generating, by the device, a transaction analysis result;   storing, by the device, the transaction data and the transaction signature;   analyzing, by the device, whether the transaction analysis result is or is not a transaction authorization;   only if the transaction analysis result is a transaction authorization, getting, by the device, service data based upon the received data;   sending, by the device, to a first external entity the service data; and   sending, by the device, the transaction data and the transaction signature to either the first external entity or a second external entity.   
     
     
         2 . Method according to  claim 1 , wherein the device accesses a public key relating to a service provider, and the method further includes the following steps:
 the device receives, besides data, a data signature relating to a service provider;   the device verifies whether the data signature is or is not valid by using the received data and the public key relating to the service provider;   only if the data signature is valid, then the device gets, based upon the received data, transaction data.   
     
     
         3 . Method according to  claim 1 , wherein, prior to getting transaction data, the method further includes the following steps:
 the device analyses whether the received data is or is not valid;   only if the received data is valid, then the device gets, based upon the received data, transaction data.   
     
     
         4 . Method according to  claim 1 , wherein, prior to signing the transaction data, the method further comprises the following step:
 only if the device authenticates successfully a user of the device, then the device signs the transaction data.   
     
     
         5 . Method according to  claim 1 , wherein, prior to getting, based upon the received data, transaction data, the data storing means storing a decipherment key relating to the service provider, the method further includes a step in which the device deciphers the received data to get data in plain text. 
     
     
         6 . Method according to  claim 1 , wherein, the data storing means stores a kernel application, the data storing means stores an application relating to a transaction processing, as a first application, and the method includes the following steps:
 the kernel application sends to the first application a message including a request for performing a transaction and the transaction data;   the first application signs the transaction data by using the private key, a signature operation result being a transaction signature;   the first application generates a transaction analysis result;   the first application sends to the kernel application the transaction data, the transaction signature and the transaction analysis result;   the kernel application stores the transaction data and the transaction signature;   the kernel application verifies whether the transaction analysis result is or is not a transaction authorization;   only if the transaction analysis result is a transaction authorization, then the kernel application gets, based upon the received data, service data;   the kernel application or a second application relating to a service provider and being stored within the data storing means sends to a first external entity the service data;   the kernel application or the second application sends the transaction data and the transaction signature to either the first external entity or a second external entity.   
     
     
         7 . Method according to  claim 6 , wherein the method further comprises the following steps:
 the second application removes the service data; and/or   the kernel application removes the transaction data and the transaction signature.   
     
     
         8 . Method according to  claim 6 , wherein, prior to getting the transaction data, a counter is initially set to an initial value, the counter being incremented, each time, the kernel application stores newly the transaction data and the transaction signature, and the method further comprises the following steps:
 the kernel application analyses whether the counter is less than or equal to a predetermined threshold value; and   only if the counter is less than or equal to the predetermined threshold value, the kernel application gets the transaction data.   
     
     
         9 . Method according to  claim 1 , wherein the transaction data includes at least one element of a group comprising:
 at least one identifier;   device user information;   at least one transaction status;   a transaction amount;   a transaction currency;   a transaction date;   a transaction type and description;   at least one transaction cryptogram;   at least one transaction security parameter.   
     
     
         10 . A device for accessing a service, wherein, the device comprises data storing means, and the device is configured to:
 receive data;   get, based upon the received data, transaction data;   sign the transaction data by using a private key relating to a transaction processing, a signature operation result being a transaction signature;   generate a transaction analysis result;   store the transaction data and the transaction signature;   analyse whether the transaction analysis result is or is not a transaction authorization;   get, only if the transaction analysis result is a transaction authorization, based upon the received data, service data;   send to a first external entity the service data; and   send the transaction data and the transaction signature to either the first external entity or a second external entity.

Join the waitlist — get patent alerts

Track US2018018665A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.